CVE Feed

    Dashboard / CVE

    8.5
    High

    CVE-2025-67518

    Last Modified: 27 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Accordion Slider PRO accordion_slider_pro allows Blind SQL Injection.This issue affects Accordion Slider PRO: from n/a through <= 1.2.

    Published: 9 Dec 2025
    8.5
    High

    CVE-2025-67517

    Last Modified: 27 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in artplacer ArtPlacer Widget artplacer-widget allows Blind SQL Injection.This issue affects ArtPlacer Widget: from n/a through <= 2.22.9.2.

    Published: 9 Dec 2025
    8.5
    High

    CVE-2025-67516

    Last Modified: 27 Apr 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-67515

    Last Modified: 27 Apr 2026

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.5.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67474

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Ultimate Member ForumWP forumwp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ForumWP: from n/a through <= 2.1.4.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67473

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in codeworkweb CWW Companion cww-companion allows Cross Site Request Forgery.This issue affects CWW Companion: from n/a through <= 1.3.2.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67472

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5.5.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67471

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal Quick Contact Form quick-contact-form allows Cross Site Request Forgery.This issue affects Quick Contact Form: from n/a through <= 8.2.5.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67470

    Last Modified: 15 Apr 2026

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Essential Plugin Portfolio and Projects portfolio-and-projects allows Retrieve Embedded Sensitive Data.This issue affects Portfolio and Projects: from n/a through <= 1.5.5.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67469

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in kubiq PDF Thumbnail Generator pdf-thumbnail-generator allows Cross Site Request Forgery.This issue affects PDF Thumbnail Generator: from n/a through <= 1.4.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67468

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in CRM Perks Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms cf7-salesforce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms: from n/a through <= 1.4.6.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67466

    Last Modified: 27 Apr 2026

    Missing Authorization vulnerability in sergiotrinity Trinity Audio trinity-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Trinity Audio: from n/a through <= 5.23.3.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-67465

    Last Modified: 27 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud Simple Link Directory simple-link-directory allows Cross Site Request Forgery.This issue affects Simple Link Directory: from n/a through <= 8.8.3.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66534

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Elated-Themes The Aisle theaisle allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Aisle: from n/a through <= 2.9.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66532

    Last Modified: 29 Apr 2026

    Missing Authorization vulnerability in Mikado-Themes Powerlift powerlift allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Powerlift: from n/a through < 3.2.1.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66531

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Dimitri Grassi Salon booking system salon-booking-system allows Cross Site Request Forgery.This issue affects Salon booking system: from n/a through <= 10.30.3.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66530

    Last Modified: 28 Apr 2026

    Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Webba Booking: from n/a through <= 6.2.1.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66529

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This issue affects Chartify: from n/a through <= 3.6.3.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66528

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Thank You Page Customizer for WooCommerce: from n/a through <= 1.1.8.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66527

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in VanKarWai Lobo lobo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Lobo: from n/a through <= 2.8.6.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66526

    Last Modified: 15 Apr 2026

    Missing Authorization vulnerability in Essekia Tablesome tablesome allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Tablesome: from n/a through <= 1.1.34.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-66525

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Elastic Email Elastic Email Sender elastic-email-sender allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Elastic Email Sender: from n/a through <= 1.2.20.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-64257

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Joe Dolson My Tickets my-tickets allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Tickets: from n/a through <= 2.1.0.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-64256

    Last Modified: 23 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PressTigers Simple Folio simple-folio allows Cross Site Request Forgery.This issue affects Simple Folio: from n/a through <= 1.1.0.

    Published: 9 Dec 2025
    2.7
    Low

    CVE-2025-64255

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Bowo Admin and Site Enhancements (ASE) admin-site-enhancements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Admin and Site Enhancements (ASE): from n/a through <= 8.0.8.

    Published: 9 Dec 2025
    2.7
    Low

    CVE-2025-64254

    Last Modified: 23 Apr 2026

    Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through <= 1.5.1.

    Published: 9 Dec 2025
    8.7
    High

    CVE-2025-9368

    Last Modified: 15 Apr 2026

    A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device.

    Published: 9 Dec 2025
    8.7
    High

    CVE-2025-12807

    Last Modified: 15 Apr 2026

    A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive database operations through exposed API endpoints.

    Published: 9 Dec 2025
    4.3
    Medium

    CVE-2025-12558

    Last Modified: 22 Apr 2026

    The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via the 'get_attachment_sizes' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including the path and meta data of private attachments, which can be used to view the attachments.

    Published: 9 Dec 2025
    7.2
    High

    CVE-2025-12705

    Last Modified: 22 Apr 2026

    The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in the 'trim_text' function in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 2.5.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-10876

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Cross-Site Scripting (XSS). This issue affects e-BAP Automation: from 1.8.96 before v.41815.

    Published: 9 Dec 2025
    6.1
    Medium

    CVE-2025-12381

    Last Modified: 17 Dec 2025

    Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the parameters of a command that is approved in the sudoers file.  This issue affects Firewall Analyzer: A33.0, A33.10.

    Published: 9 Dec 2025
    5.4
    Medium

    CVE-2025-6924

    Last Modified: 5 Jun 2026

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software e-BAP Automation allows Reflected XSS. This issue affects e-BAP Automation: before 42957.

    Published: 9 Dec 2025
    8.1
    High

    CVE-2025-14333

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox ESR 140.5, Thunderbird ESR 140.5, Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-14332

    Last Modified: 20 Apr 2026

    Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

    Published: 9 Dec 2025
    6.5
    Medium

    CVE-2025-14331

    Last Modified: 20 Apr 2026

    Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-14330

    Last Modified: 20 Apr 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-14329

    Last Modified: 20 Apr 2026

    Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-14328

    Last Modified: 20 Apr 2026

    Privilege escalation in the Netmonitor component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    7.5
    High

    CVE-2025-14327

    Last Modified: 20 Apr 2026

    Spoofing issue in the Downloads Panel component. This vulnerability was fixed in Firefox 146, Thunderbird 146, Firefox ESR 140.7, and Thunderbird 140.7.

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-14326

    Last Modified: 20 Apr 2026

    Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.

    Published: 9 Dec 2025
    7.3
    High

    CVE-2025-14325

    Last Modified: 20 Apr 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-14324

    Last Modified: 20 Apr 2026

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    8.8
    High

    CVE-2025-14323

    Last Modified: 22 Apr 2026

    Privilege escalation in the DOM: Notifications component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    8
    High

    CVE-2025-14322

    Last Modified: 20 Apr 2026

    Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    9.8
    Critical

    CVE-2025-14321

    Last Modified: 20 Apr 2026

    Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

    Published: 9 Dec 2025
    2.7
    Low

    CVE-2024-56464

    Last Modified: 15 Dec 2025

    IBM QRadar SIEM 7.5 - 7.5.0 UP14 IF01 is affected by an information disclosure vulnerability involving exposure of directory information. IBM has addressed this vulnerability in the latest update.

    Published: 9 Dec 2025
    9.6
    Critical

    CVE-2025-11022

    Last Modified: 5 Jun 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting in Command Injection has been identified. This issue affects Panilux: before v.0.10.0. NOTE: The vendor was contacted and responded that they deny ownership of the mentioned product.

    Published: 9 Dec 2025
    Unknown

    CVE-2025-14319

    Last Modified: 17 Dec 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 9 Dec 2025
    5.3
    Medium

    CVE-2025-40941

    Last Modified: 10 Dec 2025

    A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks.

    Published: 9 Dec 2025